Sandworm and Ransomware Hack Cisco Firewall Manager
Cisco's Firewall Manager has been hacked by two separate groups: a Russian military intelligence unit and a ransomware operation. The attacks targeted the management center for Cisco Secure Firewalls, which holds firewall policies, device credentials, and network topologies.
The first group, tracked as UAT-12197, used a vulnerability in the FMC software to gain unauthenticated access and extract authentication data from every account on the compromised instance. The attackers also dropped a malicious Java Archive file that accepted command-line arguments and ran them through the Linux system shell.
The second group, attributed with high confidence to Sandworm, used both CVE-2026-20079 and CVE-2026-20316 to gain access. They replaced the license.tmp file on disk with a Makeself self-extracting archive containing a malicious payload, then triggered its execution with root privileges.
Cisco has confirmed three separate clusters exploiting FMC in its September 9, 2026 disclosure. The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-20079 to its KEV catalog and set today, September 12, as the mandatory patch deadline for federal civilian agencies.